conference-paper

Analyzing Attacks on Client-Side Honeypots from Representative Malicious Web Sites

Research footprint

At a glance

Citations
1
References
12
Comments
0
Paper overview

Abstract

Client-side cyberattacks are becoming more common relative to server-side cyberattacks. This work tested the ability of the honeyclient software Thug to detect malicious or compromised servers that secretly download malicious files to clients, and tested its ability to classify these exploits. We tested Thug's analysis of delivered exploits in different configurations. Results on randomly generated Internet addresses found a low rate of maliciousness of 5.6%, and results on a blacklist of 83,667 suspicious Web sites found 163 unique malware files. Thug demonstrates the usefulness of client-side honeypots in analyzing harmful data presented by malicious Web sites.

Record transparency

Publication details

DOI
10.1109/csci58124.2022.00162
OpenAlex
W4386160548
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.